'I do it because they do it': Social-Neutralisation in Information Security Practices of Saudi Medical Interns

Saad Altamimi, Karen Renaud, Timothy Storer

Research output: Chapter in Book/Report/Conference proceedingChapter

2 Citations (Scopus)
24 Downloads (Pure)

Abstract

Successful implementation of information security policies (ISP) and IT controls play an important role in safeguarding patient privacy in healthcare organizations. Our study investigates the factors that lead to healthcare practitioners' neutralisation of ISPs, leading to non-compliance. The study adopted a qualitative approach and conducted a series of semi-structured interviews with medical interns and hospital IT department managers and staff in an academic hospital in Saudi Arabia. The study's findings revealed that the MIs imitate their peers' actions and employ similar justifications when violating ISP dictates. Moreover, MI team superiors' (seniors) ISP non-compliance influence MIs tendency to invoke neutralisation techniques. We found that the trust between the medical team members is an essential social facilitator that motivates MIs to invoke neutralisation techniques to justify violating ISP policies and controls. These findings add new insights that help us to understand the relationship between the social context and neutralisation theory in triggering ISP non-compliance.
Original languageEnglish
Title of host publicationCRiSIS 2019
Subtitle of host publicationRisks and Security of Internet and Systems
Place of PublicationCham
PublisherSpringer
Pages227-243
Number of pages17
ISBN (Electronic)9783030415686
ISBN (Print)9783030415679
DOIs
Publication statusPublished - 16 Feb 2020
Event14th International Conference on Risks and Security of Internet and Systems: CRiSIS 2019 - Hammamet, Tunisia
Duration: 29 Oct 201931 Oct 2019

Conference

Conference14th International Conference on Risks and Security of Internet and Systems: CRiSIS 2019
Abbreviated titleCRiSIS 2019
Country/TerritoryTunisia
CityHammamet
Period29/10/1931/10/19

Keywords

  • neutralisation theory
  • health care
  • iInformation security policies
  • privacy
  • medical interns

Fingerprint

Dive into the research topics of ''I do it because they do it': Social-Neutralisation in Information Security Practices of Saudi Medical Interns'. Together they form a unique fingerprint.

Cite this